HN user

33Backpack33

6 karma
Posts1
Comments23
View on HN
Password Managers 5 years ago

As far as I can tell Bitwarden doesn't inject any scripts. I know people complain it doesn't have that overlay like LastPass has but Bitwarden not having might be a plus now.

If we all agree it's not secure then why do we keep using it?

I rather have a unique password then rely on SMS anything especially if that account allows you to reset your password by SMS.

Nothing more lazy than doing something like generate a password for the user. The way most browsers work you have to go out of your way to not let it save and fill passwords.

If you create the password for the user they can't reuse it and thus no credential stuffing problems.

If they made it that far to get your password why do they need to log into your account? Having multiple locks on your door don't matter if they got in through a window.

If it's nothing new then why do people keep saying it's better to have SMS 2FA then to not have it. The research says "websites should eliminate SMS based MFA altogether".